Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-9680

Опубликовано: 16 окт. 2014
Источник: redhat
CVSS2: 3
EPSS Низкий

Описание

sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives.

It was discovered that sudo did not perform any checks of the TZ environment variable value. If sudo was configured to preserve the TZ environment variable, a local user with privileges to execute commands via sudo could possibly use this flaw to achieve system state changes not permitted by the configured commands. Note: The default sudoers configuration in Red Hat Enterprise Linux removes the TZ variable from the environment in which commands run by sudo are executed.

Отчет

This issue did not affect the default sudo configuration in Red Hat Enterprise Linux 5, 6, and 7.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4sudoWill not fix
Red Hat Enterprise Linux 5sudoWill not fix
Red Hat Enterprise Linux 6sudoFixedRHSA-2015:140920.07.2015
Red Hat Enterprise Linux 7sudoFixedRHBA-2015:242419.11.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1191144sudo: unsafe handling of TZ environment variable

EPSS

Процентиль: 59%
0.00377
Низкий

3 Low

CVSS2

Связанные уязвимости

CVSS3: 3.3
ubuntu
больше 8 лет назад

sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives.

CVSS3: 3.3
nvd
больше 8 лет назад

sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives.

CVSS3: 3.3
debian
больше 8 лет назад

sudo before 1.8.12 does not ensure that the TZ environment variable is ...

suse-cvrf
около 10 лет назад

Security update for sudo

CVSS3: 3.3
github
больше 3 лет назад

sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives.

EPSS

Процентиль: 59%
0.00377
Низкий

3 Low

CVSS2